<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bypassing IPS Protections - MySQL in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bypassing-IPS-Protections-MySQL/m-p/13543#M58366</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reminder, I keep forgetting about the columns that are hidden by default. I can narrow down my exception for the host based on the service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Nov 2018 09:01:08 GMT</pubDate>
    <dc:creator>Michael_Horne</dc:creator>
    <dc:date>2018-11-08T09:01:08Z</dc:date>
    <item>
      <title>Bypassing IPS Protections - MySQL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bypassing-IPS-Protections-MySQL/m-p/13539#M58362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am a bit of the Threat Protection / IPS newbie.&amp;nbsp; I have done a bit of a search for this issue, but I do not find something matching&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a service definition for MySQL that matches TCP port 3306. We have an SAP application that is also using TCP port 3306, but not for MySQL.&amp;nbsp; This was triggering an IPS event that was in "prevent" and was blocking the traffic:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="IPS Event" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/73174_Detect.png" /&gt;&lt;/P&gt;&lt;P&gt;Note: I have managed to enter a global exception for the destination server so that the action is only "detect".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to have no MySQL traffic to be able to use TCP port 3306 without triggering this protection. I cannot directly create an exception like I have for other IPS protection based on source and destination etc. I get the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/73181_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The protection details in the log do not provide any helpful information about what is actually being triggered:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/73183_pastedImage_4.png" /&gt;&lt;/P&gt;&lt;P&gt;The only IPS protection that I find that seems to match is "General Settings"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-4" src="https://community.checkpoint.com/legacyfs/online/checkpoint/73184_pastedImage_5.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I look at the details of this protection, the only thing I can do is to change the port associated with MySQL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-5 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/73185_pastedImage_6.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could change port associated with MySQL for the IPS, but I do not want to do this for three reason:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;I might want the IPS to detect SQL traffic when it is suing the default port.&lt;/LI&gt;&lt;LI&gt;Changing the port, will just move the same problem to a different port, that might eventually block another application.&lt;/LI&gt;&lt;LI&gt;This doesn't seem like the "best practices" solution to the problem.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It appears to me that the IPS is assuming the traffic is MySQL based on the TCP port and the applying a protocol analysis / validation based on&amp;nbsp;this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For this application I have a known / single source and a known / single destination and ideally I would like to disable this protection for this particular source / destination pair.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only IPS protection that might match this is call "non compliant MySQL".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-6 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/73186_pastedImage_7.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do no know if adding a&amp;nbsp;protection for this will help or not. If this was the IPS protection was involved. I would have expected the original log message would have mentioned this in the protection details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the moment I have added an exception for the destination server as the "protected Scope" that has an action of "Detect", but as I cannot match the protection "My SQL - General Settings", I have had to set "Detect" for all IPS detections for the destination host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-7 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/73187_pastedImage_8.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2018 21:37:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bypassing-IPS-Protections-MySQL/m-p/13539#M58362</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2018-11-05T21:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing IPS Protections - MySQL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bypassing-IPS-Protections-MySQL/m-p/13540#M58363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can try narrowing the exception down by:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/73192_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And being a lot more specific with source, destination and service port.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2018 23:22:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bypassing-IPS-Protections-MySQL/m-p/13540#M58363</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-11-05T23:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing IPS Protections - MySQL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bypassing-IPS-Protections-MySQL/m-p/13541#M58364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is hard if you have MySQL Servers on your site that need to be accessed thru the GW. Otherwise, you can deactivate the protection completely...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2018 08:36:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bypassing-IPS-Protections-MySQL/m-p/13541#M58364</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-11-06T08:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing IPS Protections - MySQL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bypassing-IPS-Protections-MySQL/m-p/13542#M58365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why don't you use a different profile for that server that doesn't include the appropriate signature?&amp;nbsp;&lt;/P&gt;&lt;P&gt;In other words, create another rule just for the affected server? (Put it in the Protected Scope)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2018 21:06:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bypassing-IPS-Protections-MySQL/m-p/13542#M58365</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-06T21:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing IPS Protections - MySQL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bypassing-IPS-Protections-MySQL/m-p/13543#M58366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reminder, I keep forgetting about the columns that are hidden by default. I can narrow down my exception for the host based on the service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2018 09:01:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bypassing-IPS-Protections-MySQL/m-p/13543#M58366</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2018-11-08T09:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing IPS Protections - MySQL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bypassing-IPS-Protections-MySQL/m-p/13544#M58367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of the reasons for deploying the Security gateways is for network segregation and also for traffic visibility. At the moment they are not fully aware of all the traffic flowing on the LAN environment. If we discover that there is no MYSQL we can do this. The risk being that later someone deploys a MySQL server without notifying anyone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2018 09:06:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bypassing-IPS-Protections-MySQL/m-p/13544#M58367</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2018-11-08T09:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing IPS Protections - MySQL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bypassing-IPS-Protections-MySQL/m-p/13545#M58368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would work, but it my opinion that this is "slippery slope" that I do not want to start walking one.&amp;nbsp; Once we have a dedicated profile for one server we might easily&amp;nbsp;start adding customized profiles for other servers. then I am drowning in profiles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A customized profile just for the server was one option that I did not think about. So thanks for mentioning. Options are always good when looking for a solution!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2018 09:10:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bypassing-IPS-Protections-MySQL/m-p/13545#M58368</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2018-11-08T09:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: Bypassing IPS Protections - MySQL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bypassing-IPS-Protections-MySQL/m-p/123122#M58369</link>
      <description>&lt;P&gt;I am having the same issue with one server.&amp;nbsp; Are we sure that the protection preventing traffic is the "Non compliant MySQL" one?&amp;nbsp; I also see the Threat Cloud "MySQL - General Settings" protection and the only thing I can change is the port number like you mentioned, I don't seem to have an option to set it to detect, inactive, etc.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 20:40:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bypassing-IPS-Protections-MySQL/m-p/123122#M58369</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2021-07-06T20:40:52Z</dc:date>
    </item>
  </channel>
</rss>

